BetaArchive Logo
Total Current Archive Size: 4765.54GB in 15409 files
Navigation Home Screenshots Image Uploader Server Info FTP Servers Wiki Forum RSS Feed Rules Please Donate
UP: 7d, 13h, 52m | CPU: 19% | MEM: 5123MB of 12279MB used
{The community for beta collectors}

Forum rules


Before you post, please make sure...

- ...your topic is related to betas or abandonware. If it is not, don't post it here. Better help sites exist else where.
- ...you have first used Google to look for an answer, and you have asked other people you know via other methods (IM, e-mail, etc).
- ...your question has not been asked before. Search the forum first before posting.

If you meet those criteria, go ahead and post your question. Be sure to provide as much information you can about the problem and how to recreate it. Also provide information on hardware and software if applicable.


Post new topic Reply to topic  [ 12 posts ] 
Author Message
 PostPost subject: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 12:18 am 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Thu Sep 17, 2009 7:37 pm

Posts
486

Favourite OS
LH 4074
I set up Win2000 Server in VPC2007 to test things out and hopefully roll out a brand new site by September. I was getting ready to finish testing DNS when this happened :
Image

This "VMWare Service" started crashing en-masse and because the default recovery action was to restart the service I quickly opened Task Manager and ran services.msc to stop that thing before it crashed the entire system.

To be honest I have absolutely no clue whatsoever as to how something labelled VMWare ended up in VPC. Since I was testing a server, I had no reason at all to screw around with stuff from VMWare (hell knows for what reason I'd do that though). My guess is that a virus slipped through. I'll see what I can do about it.

EDIT: Forgot to mention : as a side effect, when that serviced crashed, it crashed the shell too, that's why I had to use Task Manager.
EDIT2: path to the culprit is this : C:\WINNT\system\VMwareService.exe . In System, eh ? FFS I'm running NT not 9x, at least they could've been more clever and placed it in System32 like it was supposed to for any normal 32-bit NT system !


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 5:54 am 
Guru Beta Collector
Guru Beta Collector
User avatar
Offline

Joined
Tue Jul 27, 2010 2:12 am

Posts
754

Location
C:\

Favourite OS
Windows 7, Windows XP SP3...
This is quite strange. Any error codes? Anything specific?

_________________
Oops!


Top  Profile  WWW
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 7:42 am 
Amateur Beta Collector
Amateur Beta Collector
User avatar
Offline

Joined
Mon Jan 23, 2012 2:48 pm

Posts
281

Location
guess it

Favourite OS
whistler2296
Just for your information VMware does not have a service named "VMwareService".

I use VMware Workstation and in a virtual machine I only have these VMware related services starting with VMware:
Image

And in physical PC there are following:
Image

It is probable that your system is infected by some malware.
-------------------------------------
You may mount the VHD to your physical PC and scan for viruses inside it, or simply delete the VM and re-create one.

_________________
Intel i3 330M @2.13GHz/Intel HM55/8192MB DDR3 1066MHz/AMD HD 5650M/Hitachi 750GB SATA II 5400 rpm


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 9:44 am 
1337 Beta Collector
1337 Beta Collector
Offline

Joined
Tue Dec 14, 2010 4:02 pm

Posts
5354
Malware for sure... See if you can remove it, otherwise you'll have to re-install the OS...

_________________
Image
BA Wiki page | Development blog


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 10:59 am 
Pro Beta Collector
Pro Beta Collector
User avatar
Offline

Joined
Sun Feb 01, 2009 4:04 pm

Posts
583

Location
Germany , Northrhine-Westphalia

Favourite OS
Windows 2000 Professional SP4
Make sure the VM is independent from the host machine (no Shared Machine/Folder), because the malware could infect your machine (-> host) too.

_________________
Image


Top  Profile  WWW
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 11:27 am 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Thu Sep 17, 2009 7:37 pm

Posts
486

Favourite OS
LH 4074
Aparently my last edit wasn't registered. Thanks for the images PlyrStar93, I'm used to using VPC so I wasn't sure if that name was legit or not.
Anyway, I tracked the buggers from Process Explorer and removed them (there were like two other rouge processes running). VMWare Service also had to be removed from the registry.

They sure work fast. Only a couple of hours passed since I installed the system. Next time I'll start looking through TechNet for articles on network security.
By the way, just for kicks, is it possible to "extract" NepTune's firewall and install it on NT5 ? Or did they integrate it deep in the system ?


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 11:46 am 
1337 Beta Collector
1337 Beta Collector
Offline

Joined
Tue Dec 14, 2010 4:02 pm

Posts
5354
Neptune's firewall really isn't a firewall --> it's just a checkbox on network connection properties that says "Enabled firewall mode for this connection.". So far, no settings interface was found whatsoever...

_________________
Image
BA Wiki page | Development blog


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 11:48 am 
Pro Beta Collector
Pro Beta Collector
User avatar
Offline

Joined
Sun Feb 01, 2009 4:04 pm

Posts
583

Location
Germany , Northrhine-Westphalia

Favourite OS
Windows 2000 Professional SP4
I don't know exactly if it is possible to extract Neptunes Firewall (is this a real firewall?) but...
For Antivirus maybe:
- AntiVir Free
or
- Avast
and for a Firewall maybe:
- Sygate Personal Firewall Version 5.5 (5.6 is unstable)
or
- ZoneAlarm Firewall

_________________
Image


Top  Profile  WWW
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sat Jul 14, 2012 12:47 pm 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Thu Sep 17, 2009 7:37 pm

Posts
486

Favourite OS
LH 4074
I was thinking about ClamWin being open-source (and because just about any AV license is overpriced) but I'm not too sure about its detection rate. I know it doesn't offer real-time protection but that's about it.

Started following this TechNet article, quite an interesting read.
I installed Sygate (really awesome firewall, thanks ViennaXP !), updated IE but for some odd reason I can't use the Windows Update site (Error number: 0x800B0109).
Based on a quick search, it seems to be a activex or certificate problem. I configured the local policies to prompt on all non-driver installs and approved every single message that popped in the browser. I also added update.microsoft.com to the Trusted sites list but nothing changed.

I never had any problems in updating the Workstation version of 2000 so perhaps there's a server-specific security issue.


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Sun Jul 15, 2012 1:27 pm 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Thu Sep 17, 2009 7:37 pm

Posts
486

Favourite OS
LH 4074
Don't want to clutter the forum with another thread so I'll repurpose this one since the issue's somewhat connected.
I solved the update issue by manually patching with Update Rollup 1, USP5.1 and UUpdate Rollup 2.

I also installed F-Prot as an AV because I remember using it a good couple of years ago and it was pretty lightweight and decent. Finally I ran Base Security Analyzer and solved all outstanding issues mentioned in its report.

My new problem now is with Exchange 5.5 and Internet Mail Service. DNS is up and running properly, incoming mail is received properly yet I can't send any mail.
My Link Monitor doesn't show anything unusual, Internet Mail Service doesn't show any incoming mails in Queues and I don't receive any message delivery failure / delay notifications.

I'm certain there's a configuration error but I have no idea what I forgot to set up / what I configured improperly.
Or maybe my domain is getting filtered by the hotmail, yahoo! servers ? (my Exchange server uses a .tk domain so perhaps their filters associate it with spam and other malicious traffic since its a free domain)

EDIT: Forgot to mention, I updated Exchange 5.5 to SP4 so that OWA may run.
EDIT2: Connected to mx1.hotmail.com through Telnet and found out my problem. I'll have to contact my ISP for this...

Thanks everyone for your support !


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Mon Jul 23, 2012 1:25 am 
Newbie Beta Collector
Newbie Beta Collector
Offline

Joined
Sun May 15, 2011 9:18 am

Posts
10

Favourite OS
Whatever I wanna boot today
If it were "VMWare Tools" it'd be just a buggy VMWare integration, but "VMWareService" sounds awfully fishy.


Top  Profile
 PostPost subject: Re: VMWare Service running in Virtual PC ?!        Posted: Wed Aug 08, 2012 5:37 am 
Guru Beta Collector
Guru Beta Collector
User avatar
Offline

Joined
Tue Jul 27, 2010 2:12 am

Posts
754

Location
C:\

Favourite OS
Windows 7, Windows XP SP3...
Oh my! After doing a bit of research, this is likely a virus! Source: http://www.bleepingcomputer.com/startup ... 18160.html

Apparently there are two types of VMwareService.exe 's. One is legit: name "VMWare Tools Service", one is a backdoor process: name "VMWareService"
http://www.bleepingcomputer.com/startup ... 24554.html and http://www.bleepingcomputer.com/startup ... 17532.html

Interesting find. VM users beware :?

_________________
Oops!


Top  Profile  WWW
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 




Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  

All views expressed in these forums are those of the author and do not necessarily represent the views of the BetaArchive site owner.

Powered by phpBB® Forum Software © phpBB Group

Copyright © 2006-2013

 

Sitemap | XML | RSS